| File name: | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.bin.zip |
| Full analysis: | https://app.any.run/tasks/f4bde0f5-4342-44a8-bbc8-1f4c2467bc80 |
| Verdict: | Malicious activity |
| Threats: | Ficker Stealer is a malware that steals passwords, files, credit card details, and other types of sensitive information on Windows systems. It is most often distributed via phishing emails and can perform keylogging, process injection, and browser tracking. |
| Analysis date: | December 25, 2020, 10:11:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 6EE50F985FD852E0568B691056E27DBB |
| SHA1: | 75A4EC289C640F8898810F0B46233EC7585168A5 |
| SHA256: | 25C89F13797842196179947590E0CC617A58BDC86AE27C1C5D88A18495021560 |
| SSDEEP: | 3072:il9XwLXgAXhpwxzPhmcaLXWoEBlM9Wdk6lOZpS/puN+75nzmVz:iXwNx6BccQXsy9WvEZo/AN+8Vz |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2020:12:25 10:09:17 |
| ZipCRC: | 0x969b227d |
| ZipCompressedSize: | 143257 |
| ZipUncompressedSize: | 333248 |
| ZipFileName: | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.bin |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 636 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\FXSAPIDebugLogFile.txt | C:\Windows\system32\NOTEPAD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 688 | "C:\Users\admin\AppData\Local\Temp\installer.exe" | C:\Users\admin\AppData\Local\Temp\installer.exe | installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 772 | "C:\Users\admin\Desktop\Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe" | C:\Users\admin\Desktop\Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1488 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.bin.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2444 | "C:\Users\admin\AppData\Local\Temp\installer.exe" | C:\Users\admin\AppData\Local\Temp\installer.exe | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3916 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.bin.zip | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1488) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\__rzi_1488.43418 | — | |
MD5:— | SHA256:— | |||
| 1488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb1488.43662\Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | — | |
MD5:— | SHA256:— | |||
| 2444 | installer.exe | C:\Users\admin\AppData\Roaming\530354923 | — | |
MD5:— | SHA256:— | |||
| 688 | installer.exe | C:\ProgramData\kaosdma.txt | text | |
MD5:— | SHA256:— | |||
| 688 | installer.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\3N0L4GH1.txt | text | |
MD5:— | SHA256:— | |||
| 772 | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | C:\Windows\System32\drivers\etc\hosts | text | |
MD5:— | SHA256:— | |||
| 1488 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.bin.zip | compressed | |
MD5:— | SHA256:— | |||
| 772 | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | C:\Users\admin\AppData\Local\Temp\installer.exe | executable | |
MD5:— | SHA256:— | |||
| 2444 | installer.exe | C:\Users\admin\AppData\Local\Temp\nsfE212.tmp\System.dll | executable | |
MD5:FCCFF8CB7A1067E23FD2E2B63971A8E1 | SHA256:6FCEA34C8666B06368379C6C402B5321202C11B00889401C743FB96C516C679E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
772 | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | GET | 301 | 162.0.209.225:80 | http://brokstrot.com/c.txt | CA | html | 235 b | suspicious |
— | — | GET | 200 | 151.139.128.14:80 | http://crl.comodoca.com/AAACertificateServices.crl | US | der | 506 b | whitelisted |
— | — | GET | 200 | 151.139.128.14:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEG7AChe%2BLVtylIzsmFEcl7A%3D | US | der | 471 b | whitelisted |
— | — | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
688 | installer.exe | GET | 200 | 50.19.252.36:80 | http://api.ipify.org/?format=xml | US | text | 13 b | shared |
772 | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | GET | 301 | 162.0.209.225:80 | http://brokstrot.com/blink.php?name=Cyberpunk%202077%20(Unlocked%20Downloader)%20%5BCODEX%5D%20FULL | CA | html | 308 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
772 | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | 162.0.209.225:80 | brokstrot.com | AirComPlus Inc. | CA | suspicious |
772 | Cyberpunk 2077 (Unlocked Downloader) [CODEX] FULL.exe | 162.0.209.225:443 | brokstrot.com | AirComPlus Inc. | CA | suspicious |
— | — | 151.139.128.14:80 | crl.comodoca.com | Highwinds Network Group, Inc. | US | suspicious |
688 | installer.exe | 85.17.190.28:80 | — | LeaseWeb Netherlands B.V. | NL | malicious |
688 | installer.exe | 50.19.252.36:80 | api.ipify.org | Amazon.com, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
brokstrot.com |
| suspicious |
crl.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
api.ipify.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
688 | installer.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup (ipify .org) |
688 | installer.exe | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
688 | installer.exe | A Network Trojan was detected | STEALER [PTsecurity] Ficker |
688 | installer.exe | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
688 | installer.exe | A Network Trojan was detected | STEALER [PTsecurity] Ficker |